<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Josh Liburdi on joshliburdi.com</title><link>https://joshliburdi.com/</link><description>Recent content in Josh Liburdi on joshliburdi.com</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 02 Jul 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://joshliburdi.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Achieving Exactly Once Semantics in AWS</title><link>https://joshliburdi.com/writing/2024_aws_exactly_once_semantics/</link><pubDate>Tue, 02 Jul 2024 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2024_aws_exactly_once_semantics/</guid><description>WTF are Semantics? If you spend even a little bit of time reading about or building distributed systems, eventually you come to understand that there are three types of message delivery guarantees:
At-most once: Message delivery is not guaranteed. At-least once: Messages delivery is guaranteed with possible duplication. Exactly once: Message delivery is guaranteed with no duplication. Ensuring that these semantics are met is a shared responsibility between the message queue &amp;ndash; in this post, I&amp;rsquo;ll cover some popular AWS services &amp;ndash; and the producer or consumer of messages (i.</description></item><item><title>Reduce AWS Kinesis Costs by 80% with this One Weird Trick</title><link>https://joshliburdi.com/writing/2024_reduce_aws_kinesis_costs/</link><pubDate>Sat, 15 Jun 2024 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2024_reduce_aws_kinesis_costs/</guid><description>The Trick Aggregate multiple records into a single aggregated record. That’s it.
Why It Works The AWS Kinesis Data Streams service bills based on two criteria: the number of shards running per hour (“shard hours”) and the amount of bytes per record put into each stream. Each shard has a maximum capacity (either 1,000 records written per second or 1 MB written per second) and while there are potential savings in managing shard hours, the greater cost savings is in managing record sizes.</description></item><item><title>Bluenomicon: Building Loosely Coupled Threat Detection Systems</title><link>https://joshliburdi.com/writing/2023_bluenomicon/</link><pubDate>Sat, 01 Apr 2023 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2023_bluenomicon/</guid><description>I contributed the chapter &amp;ldquo;Building Loosely Coupled Threat Detection Systems&amp;rdquo; to Splunk SURGe&amp;rsquo;s book, Bluenomicon: The Network Defender’s Compendium. The book is a collection of essays from security professionals on a variety of topics, from threat hunting to incident response to cloud security, and it&amp;rsquo;s &amp;ldquo;free&amp;rdquo; (requires contact info). I also have several physical copies if anyone wants one.</description></item><item><title>Announcing Substation</title><link>https://joshliburdi.com/writing/2022_announcing_substation/</link><pubDate>Tue, 25 Oct 2022 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2022_announcing_substation/</guid><description>Over on Brex&amp;rsquo;s tech blog I wrote a post announcing the release of Substation. The original text is copied below.
Introduction We are thrilled to publicly announce the release of Substation, an open source toolkit for creating highly configurable, no maintenance, and cost-efficient data pipelines. Substation solves a problem that every security team has, but few may recognize - the need to normalize, correlate, and enrich their security event data at scale.</description></item><item><title>Structured &amp; Task-Driven Threat Hunting</title><link>https://joshliburdi.com/writing/2020_structured_threat_hunting/</link><pubDate>Sun, 29 Mar 2020 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2020_structured_threat_hunting/</guid><description>Preamble In October 2019 I joined the Splunk Global Security organization to build Splunk&amp;rsquo;s internal threat hunting program. Over a few months we went from an organization with no defined hunting program to one that can do full-scale, high-value hunting. This post describes how individual hunts can be structured to maintain focus and avoid &amp;ldquo;rabbit holes.&amp;rdquo;
Before diving into this topic, I recommend that you take a moment to watch this presentation from Justin Kohler and Patrick Perry &amp;ndash; it covers some of the concepts described here.</description></item><item><title>Creating &amp; Tracking Threat Hunting Metrics</title><link>https://joshliburdi.com/writing/2020_threat_hunting_metrics/</link><pubDate>Sat, 28 Mar 2020 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2020_threat_hunting_metrics/</guid><description>Preamble In October 2019 I joined the Splunk Global Security organization to build Splunk&amp;rsquo;s internal threat hunting program. Over a few months we went from an organization with no defined hunting program to one that can do full-scale, high-value hunting. This post describes the metrics used to evaluate a hunting program.
Measuring Success Before we operationalized our hunting program, I knew that metrics tracking needed to be a part of everything we did.</description></item><item><title>Not Today, Microservices!</title><link>https://joshliburdi.com/writing/2019_not_today_microservices/</link><pubDate>Sat, 02 Mar 2019 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2019_not_today_microservices/</guid><description>This post is additional content for my presentation at 2019&amp;rsquo;s BSides SF conference that describes the decision to not build Strelka with a microservices architecture.
Here&amp;rsquo;s my take on microservices: they&amp;rsquo;re for the 0.01% of application owners. Microservices, like any system architecture model, have advantages and disadvantages; for the majority of systems (including Strelka), I think the disadvantages outweigh the advantages. Don&amp;rsquo;t just take it from me, here&amp;rsquo;s a quote from Martin Fowler, an often-quoted proponent of microservices, taken from a blog entry named Microservice Premium:</description></item><item><title>Remote Packet Retrieval with Stenographer and gRPC</title><link>https://joshliburdi.com/writing/2019_stenographer_grpc/</link><pubDate>Sun, 20 Jan 2019 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2019_stenographer_grpc/</guid><description>This post describes the process of building a secure packet capture (PCAP) retrieval service for Google&amp;rsquo;s Stenographer using gRPC and Python. The service allows clients to securely request PCAP from a server running Stenographer and stream the PCAP back to the client.
Components of Stenographer Stenographer contains several utilities (stenotype, which writes packets to disk; stenocurl, which interacts with the Stenographer system; etc.), but for this service we only need to build on top of stenoread.</description></item><item><title>Huntpedia: Hunting for Command and Control</title><link>https://joshliburdi.com/writing/2018_huntpedia/</link><pubDate>Mon, 01 Jan 2018 00:00:00 +0000</pubDate><guid>https://joshliburdi.com/writing/2018_huntpedia/</guid><description>I contributed the chapter &amp;ldquo;Hunting for Command and Control&amp;rdquo; to Sqrrl&amp;rsquo;s book, Huntpedia: Your Threat Hunting Knowledge Compendium. The chapter was originally a blog post on the Sqrrl website and was later reused in the book. I don&amp;rsquo;t remember when the book was released, but I think it was sometime in 2018 (after I left the company). I may also have a few physical copies if anyone wants one?!
If you don&amp;rsquo;t know what Sqrrl was or what happened to it, then go here.</description></item></channel></rss>